Guide for Healthcare Practices

HIPAA File Sharing Requirements for Small Practices

HIPAA applies to practices of all sizes, a 3-person clinic has the same obligations as a hospital system. Here's what the rules actually require for sharing files that contain protected health information.

HIPAA applies to you too

Size does not determine whether HIPAA applies to your practice. Function does.

Many small practices assume HIPAA's technical requirements are designed for hospitals and large health systems. That a solo practitioner or small clinic can operate under a lighter standard. This is wrong.

Any covered entity (healthcare providers who transmit health information electronically, health plans, healthcare clearinghouses) or business associate that creates, receives, maintains, or transmits protected health information (PHI) must comply with the HIPAA Security Rule, regardless of size.

If you file electronic claims, send electronic referrals, or use any electronic system to handle patient information, you are a covered entity. The Security Rule applies to you.

The practical reality: HHS Office for Civil Rights (OCR) has investigated and fined practices with fewer than 5 employees. The 2023 OCR enforcement data shows that small practices are disproportionately targeted because they're more likely to have compliance gaps. Being small doesn't reduce your obligations. It increases your risk of being underprepared.

The HIPAA Security Rule in plain English

The Security Rule organizes its requirements into three categories of safeguards. Here's what each one means for how you share files.

Administrative Safeguards

Risk assessment

Identify where PHI lives in your practice, how it moves, and what could go wrong. This is the foundation of everything else.

Workforce training

Every staff member who touches PHI needs to understand the rules, not just the doctor. Front desk, billing, even IT contractors.

Incident response plan

When (not if) something goes wrong, you need a documented plan: who to notify, how to contain the breach, and how to report it to HHS.

Physical Safeguards

Device security

Laptops, tablets, and phones that access PHI need encryption, screen locks, and remote wipe capability. A stolen unencrypted laptop is a reportable breach.

Workstation security

Screens showing PHI should not be visible to patients in the waiting room. Auto-lock after inactivity. No shared logins.

Technical Safeguards

Access controls

Unique user IDs, role-based permissions, automatic logoff. Only the people who need PHI for their job should be able to access it.

Audit controls

Log who accessed what PHI, when, and what they did with it. You need these logs both for compliance and for investigating incidents.

Integrity controls

Mechanisms to confirm PHI hasn't been altered or destroyed improperly. This includes checksums, authentication, and version controls.

Transmission security

PHI in transit must be protected. In practice, this means TLS encryption for any data moving over a network, no exceptions.

The technical safeguards are the most directly relevant to file sharing, but all three categories apply. A compliant file sharing process requires administrative policies, physical device protections, and technical controls working together.

What HIPAA requires for file sharing specifically

When you share files containing PHI, referrals, billing records, insurance documents, lab results. These four requirements are non-negotiable.

Encryption at rest

Addressable (but practically required)

HIPAA classifies encryption at rest as "addressable," which does NOT mean optional. It means you must implement it or document why an equivalent alternative is reasonable. For file sharing involving PHI, there is no reasonable alternative to encryption. AES-256 is the standard.

Encryption in transit

Required

Any PHI moving over a network must be encrypted. TLS 1.2 is the minimum, TLS 1.3 is preferred. This applies to file uploads, downloads, API calls, and email transmissions. If your file sharing tool doesn't enforce HTTPS, it's non-compliant.

Access controls

Required

You need to control who can access shared files and verify their identity. Shared folder links with no authentication are a compliance gap. Look for per-file or per-link access restrictions, unique user identification, and automatic access expiration.

Audit trail

Required

Every access to PHI must be logged. Who viewed the file, who downloaded it, when, and from where. These logs need to be retained and reviewable. In the event of a breach investigation, HHS will ask for them.

Common HIPAA file sharing mistakes

These are the violations OCR finds most often in small practices, and every one of them is avoidable.

Using personal email for PHI

Gmail, Yahoo, and Outlook.com are not HIPAA-compliant for PHI. Even if the email provider offers encryption, personal accounts lack the administrative controls, audit logging, and BAA coverage that HIPAA requires. PHI in a personal inbox is an open breach.

Texting patient information

Standard SMS is unencrypted, stored on carrier servers, and impossible to audit or revoke. Texting a patient's lab results, diagnosis, or insurance info to a colleague is a HIPAA violation, even if it feels convenient.

Using tools without a BAA

If a vendor handles PHI on your behalf, HIPAA requires a Business Associate Agreement. Using Dropbox, Google Drive, or any file sharing tool without a signed BAA means YOU are liable for any breach on their end. Many tools offer BAAs, but you have to ask.

No audit trail on file access

If you can't answer "who accessed this patient file and when?" you have a compliance gap. Shared folders, USB drives, and consumer file sharing tools typically don't provide the access logging HIPAA requires.

Keeping PHI longer than needed

HIPAA's minimum necessary principle means you should only retain PHI for as long as it's needed for the purpose it was shared. Files sitting in a shared folder indefinitely expand your breach surface with zero benefit.

Tools that can help

No single tool makes you HIPAA compliant, compliance is an organizational responsibility, not a product feature. But the right tools make compliance achievable.

EHR built-in portals

Best for: Clinical data, lab results, patient communication

Best option for clinical workflows. Most EHRs include a patient portal that's already HIPAA-compliant. Limited for sharing with third parties outside your EHR ecosystem.

HIPAA note: Typically covered under your EHR vendor's BAA

Encrypted file transfer (e.g., DeadVault)

Best for: Billing, referrals, insurance docs, third-party sharing

Designed for exchanging documents with external parties: other providers, billing companies, attorneys. Automatic expiration helps enforce retention policies. Not a replacement for your EHR's clinical workflows.

HIPAA note: Requires separate BAA; verify encryption and audit capabilities

Encrypted email (Virtru, Paubox)

Best for: Quick communications, small attachments

Adds encryption to email workflows your staff already know. Good for messages and small files. Large file transfers or structured document exchange can be cumbersome.

HIPAA note: BAA available from most HIPAA-focused email providers

Enterprise platforms (Box, Kiteworks)

Best for: Large organizations, complex permission hierarchies

Full-featured but designed for enterprise IT departments. Can be overkill for a 5-person practice in both cost and complexity. Strong audit and compliance features if you have the staff to manage them.

HIPAA note: BAA available on healthcare/enterprise tiers

Important: Regardless of which tool you choose, you need a signed Business Associate Agreement (BAA) with any vendor that handles PHI on your behalf. The tool itself doesn't make you compliant. Your policies, training, risk assessments, and documentation do. Tools are one component of a compliance program, not a substitute for one.

Frequently asked questions

Common questions about HIPAA file sharing requirements for small practices.

Yes. If your file sharing vendor stores, processes, or transmits PHI on your behalf, they are a business associate under HIPAA, and you must have a signed Business Associate Agreement before sharing any PHI through their platform. This applies to cloud storage, file transfer tools, email providers, and any other service that touches PHI. Without a BAA, you bear full liability for any breach on their end.
Google will sign a BAA for Google Workspace (formerly G Suite) paid accounts, but signing a BAA alone does not make it compliant. You must also configure it properly: disable link sharing on files containing PHI, enforce 2FA, configure data loss prevention rules, restrict sharing to authorized domains, and train staff on proper usage. Google explicitly states that its BAA does not cover consumer Gmail accounts, only paid Workspace accounts with the BAA executed.
HIPAA penalties are tiered based on the level of negligence. Tier 1 (unaware): $100-$50,000 per violation. Tier 2 (reasonable cause): $1,000-$50,000 per violation. Tier 3 (willful neglect, corrected): $10,000-$50,000 per violation. Tier 4 (willful neglect, not corrected): $50,000 per violation. Annual maximum is ~$2 million per violation category. Criminal penalties can include up to 10 years imprisonment. For small practices, even a Tier 1 finding can be financially devastating.
HIPAA does not mandate a specific encryption algorithm, but it references NIST standards. In practice, this means AES-128 or AES-256 for data at rest and TLS 1.2+ for data in transit. AES-256 is the most widely recommended and is what most HIPAA-compliant tools implement. The key point: using any NIST-recognized encryption method is considered sufficient for the "addressable" encryption specification, not using encryption at all requires documented justification that HHS would find reasonable.
"Addressable" is one of the most misunderstood terms in HIPAA. It does NOT mean optional. It means you must assess whether the specification is reasonable and appropriate for your environment. If it is, and for encryption, it almost always is. You must implement it. If you determine it's not reasonable, you must document why and implement an equivalent alternative measure. "We decided not to encrypt because it's expensive" is not an acceptable justification.
Yes. HIPAA applies to all covered entities regardless of size. A covered entity is any healthcare provider that transmits health information electronically, any health plan, or any healthcare clearinghouse. A solo practitioner who files electronic claims is subject to the same HIPAA Security Rule as a 500-bed hospital. The scale of your compliance program can differ, but the requirements do not go away based on practice size.

Need secure file sharing for your practice?

DeadVault provides encrypted file transfer with automatic expiration, audit logging, and access controls. It can be one part of your HIPAA compliance toolkit, but remember, compliance starts with your policies and training.